This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Anti-Virus flagging ZoneAlarm file as suspicious

Sophos Anti-Virus 7.6.16 (with latest updates) has sent a file to quarantine which apparently belongs to ZoneAlarm.

The file in question is C:\Program Files\Checkpoint\ZAForceField\Plugins\ISWHRSRV.dll.

Sophos identifies it as suspicious, of type Sus/VB-AM.

I can find no reference to either ISWHRSRV.dll or Sus/VB-AM on either the Sophos or ZoneAlarm websites.

Does anybody know if this is really a suspicious file or is it a false trip from Sophos ?

:1463


This thread was automatically locked due to age.
  • Hi,

    "suspicious behaviour" is not based on hard facts like a known virus. It is based on a certain kind of behaviour like changing network parameters, adding autostart entries in the registry et al.

    This can and will cause false positives, as there is software which does this legitimately. Therefore, you will need to declare these applications as harmless. This is done in the AV-policy in "Authorizations".

    Since Sophos offers a full-featured firewall, I don't see a reason to use ZoneAlarm on a machine which is protected by Sophos Endpoint Security.

    Best regards,

    Detlev

    :1466
  • Hello carina,

    can't find Sus/VB-AM but Sus/VB-AN - but it probably doesn't make much difference. The reply to your post on the ZoneAlarm forums says it's legitimate.

    If you read the Action tab for the Sus/VB-Ax items you'll find the following paragraph:

    To reduce the chance of unwanted detections, Sophos HIPS should be set to 'Alert only' mode for the duration of any software installations. For more information, please read the knowledgebase article about deciding whether to allow or block a file.

    But even if you did use Alert only mode at first a file may later cause an alert. Either because it has been updated or because detection data has. It's therefore advisable to configure Cleanup for suspicious files as Deny access only.

    Usually I send in a sample in addition to authorizing it when

    a) I think it is part of an application which is widely-used (except for one-time - i.e. not part of auto-update - installers and uninstallers)

    b) the alert was caused by changed definitions (i.e. the file has been around for some time without Sophos complaining but has been detected after a detection data update)

    Christian

    :1467
  • Suspicious Files and Suspicious Behaviour differ in regard how you can treat them with Sophos:

    * Suspicious Behaviour: off, detect/alert only mode; block

    * Suspicious files: usually malware with no IDE yet. File! Block, delete, do nothing in the Cleanup section of the AV policy

    :1768
  • As Zonelabs say the file is a legitimate file belonging to their software we have set the authorisation in the Sophos Console as mentioned by a previous poster.

    :1776